CVE-2026-2287 is a critical remote code execution (RCE) vulnerability affecting CrewAI, stemming from an insufficient Docker runtime check that defaults to an exploitable sandbox environment. With a CVSS score of 9.8, this vulnerability allows an unauthenticated attacker to achieve complete system compromise over the network with low attack complexity. While no public exploit code is available and it is not on CISA's KEV, the vulnerability is on the Hot List and has garnered community and media attention, with discussions highlighting its potential for RCE via sandbox bypass.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.0CPE matchmatch criteria | cpe:2.3:a:crewai:crewai:1.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.